Salesforce Connected App Security Updates for Docusign Salesforce Integrations
08/09/2026
Docusign is updating all Docusign Salesforce integrations to align with Salesforce's latest connected app security requirements. This affects users of Docusign Apps Launcher, CLM/Gen for Salesforce, IAM for Sales, and Legacy eSignature for Salesforce. In compliance with these guidelines, we are implementing the following security controls:
Proof Key for Code Exchange (PKCE)
Refresh Token Rotation (RTR)
30-day idle timeout for refresh tokens
Refresh token IP allowlists at the connected app level
Deployment across UAT and production environments is underway through early August 2026. Please check this page for updated enforcement timelines and contact Docusign Support if any issues are encountered.
Starting August 10, 2026, we recommend installing the latest Docusign Apps Launcher 8.6.1 package from AppExchange. This update ensures compliance with the new security protocols and streamlines reconnection. We have begun upgrading customer sandbox environments to version 8.6.1 and expect to complete this within one week.